Site navigation

JD Sports Data Breach: 10 Million Customers Affected

Elizabeth Greenberg

,

jd sports data breach
The data breach affected about 10 million customers, though passwords and payment details were not accessed. 

JD Sports, the Sports and Fashion retailer, has been the latest to suffer a data breach with about 10 million customers affected.

The company announced that historical online data on customer purchases had been compromised in the attack.

Information on orders between November 2018 and October 2020 was accessed.

JD Sports brands affected include JD, Size?, Millets, Blacks, Scotts, and MittleSport.

Assuring their customers, JD Sports claimed the information was limited as they do not hold full payment card details, and at the moment they have no reason to believe that passwords were compromised in the attack.

What may have been accessed in the attack consists of costumers’ names, billing addresses, delivery addresses, emails, phone numbers, order details and the final four digits of payment cards.

In their statement, JD Sports have said they have taken the “necessary immediate steps” to handle the incident, and are working with cyber security experts. They are also cooperating with the UK’s Information Commissioner’s Office.

The company is also contacting affected customers to advise them of potential phishing scams.

Neil Greenhalg, CFO of JD Sports said: “We want to apologise to those customers who may have been affected by this incident. We are advising them to be vigilant about potential scam e-mails, calls and texts and providing details on how to report these. We are continuing with a full review of our cyber security in partnership with external specialists following this incident. Protecting the data of our customers is an absolute priority for JD.”


Recommended


At the moment, no information had been provided on the method used to access the information.

This is just the latest in UK cyber attacks, coming just one day after Data Privacy Awareness Day.

Earlier in the year, Royal Mail suffered cyber incident that severely affected its services.

Further, PayPal suffered a massive data breach due to a successful credential stuffing attack. 4

While full payment details and passwords were not accessed, the data breach could leave millions more susceptable to phishing attacks and scams.


Get all the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data